Vulnerability Development mailing list archives

Re: news story and router passwords


From: Talisker <Talisker () NETWORKINTRUSION CO UK>
Date: Thu, 12 Oct 2000 19:45:30 +0100

I've read one article recently
 http://www.denverpost.com/business/biz1012d.htm  ) in which it is clamed
that some hacker after sniffing router password changed it and made
*something* after that they were not able to recover that password. Have
somebody heard of such problems (it looks like they were using cisco,
because they say  - "If this guy posts how he actually did this, the whole
Internet's wide open." )? AFAIK ciscos have password recovery procedures,
at
least those which are not low-end.

Sniffing router passwords including the "Enable" password for a Cisco router
is easy.  However, the password must pass the sniffer therefore it is
possible that this ISP was connecting to their routers across the Internet,
in which case they got what was coming.  Alternatively an internal machine
may have been compromised and that may have sniffed the password.  I suspect
it may not have been a Cisco router as their passwords can be physically
reset at the router, therefore they may have been down for 11 hours but not
11 days.
One way to prevent all this is to use an old 486 to connect to the router's
console port and communicate with the router securely
I wrote a Cisco router security guide it's on my site below under "security
related" it's a little old but mostly still relevant

Andy
 http://www.networkintrusion.co.uk Talisker's comprehensive IDS & Scanner
List


Current thread: